I am an active member of 24 Hour Fitness. The last time I tried to sign into the gym, I was told by the associates at the front desk that I would have to sign-up for the Cardless Check-in system, which included scanning my fingerprints.
I have several concerns about a private company collecting and storing my fingerprint data. Normally fingerprint collection is reserved for criminals that have committed a criminal offense, and not someone looking to exercise at their local gym. The implementation of biometric technology does not just involve collection of information about the person, but rather information of the person, intrinsic to them.
I feel that the transition to this new system was not communicated to members. Why could it not have been communicated to members via email, and/or letter mail? Instead it has been left to the people at the front desk of 24 Hour Fitness to try and explain. When I asked why 24 Hour Fitness is suddenly changing the way a customer signs into the gym, they could only tell me that it was more convenient for the customer. I hardly think this a rationale to start collecting the fingerprints of every customer. I strongly disagree that this makes it more convenient for the customer. I refuse to use this new system, and I have been told that if I don’t use the Cardless Check-in that I will have to present my driver’s license along with my membership card every time I sign-in. This makes it very inconvenient for me. I don’t usually carry my wallet into the gym, and now I have to risk storing my wallet in my locker where it can easily be stolen.
I sited my concerns to the employees at the 24 Hour Fitness counter, but none of them were able to answer them my questions and couldn’t tell me the real reason the sign-in policy had changed. I understand how modern fingerprint biometric systems function. I understand that the fingerprint is hashed and stored in a database and compared for reverification upon sign-in. The fact that I know how this technology functions is what concerns me the most. How do I really know what 24 Hour Fitness is doing with the fingerprint that is scanned in?
Here are some of the questions I asked to the employees at the front desk and they were unable to answer.
1) What type of network security are you employing in order to protect the Cardless Check-in system?
2) What type of physical/anti-tamper mechanisms do you have implemented?
3) What secure cryptographic algorithm is being used to protect customers fingerprints (i.e. the data at rest)?
4) Is the fingerprint converted into a cryptographic one-way hash?
5) If it is a one-way hash, which algorithm is being used and what is the strength (i.e. size)?
Before the Cardless Check-in system was implemented if I lost my plastic membership card, I could simply get a new one without harm. With the Cardless Check-in system I am now putting a lifetime of trust into a private company. If the scan of my fingerprint is lost because a disgruntled employee from 24 Hour Fitness decides to steal the information or someone hacks into the system my fingerprint identity is lost forever. I have one set of fingerprints. I cannot simply re-grow a new fingerprint.
When I signed my membership I did not sign up to have my biometric fingerprint data scanned into your database. In my opinion by collecting fingerprint data, 24 Hour Fitness is starting a trend in America that undermines democracy, personal freedoms and free, open societies. I refuse to have my biometric stored by your Cardless Check-in system. I would like the Annapolis gym to allow me to enter by simply scanning the barcode of my membership card. I do not want to have to present my driver’s license or be forced into a program that I feel is intrusive, offensive, distasteful, invasive. If you are forcing me to scan my fingerprints in order to enter 24 Hour Fitness then I would like to cancel my membership.
Thank you.
Monday, August 30, 2010
My Email to '24 Hour Fitness' Concerning the Implementation of Their New 'Cardless Check-in'
Labels:
1984,
24 hour fitness,
big brother,
biometrics,
distasteful,
fingerprints,
gym,
intrusive,
invasive,
offensive,
privacy
Subscribe to:
Post Comments (Atom)
Great content, amazing post altogether! keep posting such quality posts would be delighted to be updated with the latest on your blog,
ReplyDeleteRegards
Best Routers for 2 story house